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IN THE CLAIMS 

This listing of claims will replace all prior versions and listings of claims in the 
Application: 

LISTING OF CLAIMS: 
Claims 1-8 (Canceled). 

9. (Currently Amended) Th e m e thod of c l a i m 7, th e m e thod furth e r 
compr i s i ng, A method for enabling targeted information retrieval while protecting 
consumer privacy by processing aggregated requests, the method comprising: 

(a) distributing a negotiant function for execution to a plurality of 
consumers, the negotiant function designed to produce an information request as 
output: 

(b) receiving a plurality of information requests, a first information 
request of the plurality of information requests associated with a first consumer 
and obtained by applying a first negotiant function to an element of data 
associated with the first consumer, a second information request of the plurality 
of information requests associated with a second consumer and obtained by 
applying a second negotiant function to an element of data associated with the 
second consumer: and 

after step (b), the steps of encrypting the plurality of information requests; 
and aggregating a plurality of request pairs Vi, said plurality of request pairs 
having a sequence, each of said plurality of request pairs comprising an 
encrypted information request and a consumer identifier. 

1 0. (Original) The method of claim 9, the method further comprising, the step 
of applying a mix network to said plurality of request pairs Vi to obtain a plurality 
of request pairs V 2 , the plurality of request pairs Vi having a first sequence, each 
of the plurality of request pairs V-i comprising an information request, said 
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information request encrypted with a first public key and a first random encryption 
factor, and an identifier, the plurality of request pairs V 2 having a second 
sequence comprising the first sequence permuted by a first random secret 
permutation, each of the plurality of request pairs V 2 comprising the information 
request in plaintext and the identifier encrypted with a second public key and a 
second random encryption factor. 

1 1 . (Original) The method of claim 1 0, the method further comprising, the 
step of replacing the information request in each of the plurality of request pairs 
V 2 with an element of information to create a plurality of response pairs V 2 '. 

12. (Original) The method of claim 1 1 , the method further comprising, the 
step of applying a mix network to the plurality of response pairs V 2 ' to obtain a 
plurality of response pairs V 3 , the plurality of response pairs V 3 having a third 
sequence comprising the second sequence permuted by a second random 
secret permutation, each of the plurality of response pairs V 3 comprising the 
element of information, said element of information encrypted with a third public 
key and a third random encryption factor, and the identifier in plaintext. 

1 3. (Original) The method of claim 1 2, wherein the first public key, the second 
public key, and the third public key are a single public key. 

14. (Original) The method of claim 12, the method further comprising, after 
step (b), the step of applying asymmetric proxy re-encryption to the plurality of 
response pairs V 3 to obtain a plurality of response pairs V 4 , each of the plurality 
of response pairs V 4 comprising the element of information encrypted with a 
fourth public key and the identifier in plaintext. 



U.S. Application No.: 09/802,278 Attorney Docket No.: 1 048-005 

-4- 



15. (Previously Presented) The method of claim 14, the method further 
comprising, the step of making the element of information encrypted with the 
fourth public key available to a consumer based on the identifier. 

16. (Original) The method of claim 14 wherein quorum-controlled asymmetric 
proxy re-encryption is applied to the plurality of response pairs V 3 to obtain a 
plurality of response pairs V 4 , each of the plurality of response pairs V 4 
comprising the element of information encrypted with the fourth public key and 
the identifier in plaintext. 

17. (Original) The method of claim 1 6 wherein the fourth public key is a key of 
the consumer; and wherein making the element of information encrypted with the 
fourth key available to the consumer based on the identifier comprises 
transmitting the element of information encrypted with the fourth public key to the 
consumer in response to the identifier. 

18. (Original) A method for targeted information retrieval while protecting 
consumer privacy by comparing blinded ciphertexts, the method comprising: 

(a) distributing a negotiant function for execution to a plurality of 
consumers, the negotiant function designed to produce an information request as 
output; 

(b) receiving a request pair in response to the negotiant function, the 
request pair comprising a consumer identifier and the information request and a 
first random encryption factor, the information request encrypted with the first 
public key and the first random encryption factor having a first underlying 
plaintext; 

(c) constructing a first plurality of information pairs, the first plurality of 
information pairs having a first sequence, each of the first plurality of information 
pairs comprising an element identifier and an element of information encrypted 
with a second public key and a second random encryption factor; 
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(d) applying a mix network to the first plurality of information pairs to 
obtain a second plurality of information pairs, the second plurality of information 
pairs having a second sequence comprising the first sequence permuted by a 
random secret permutation, each of the second plurality of request pairs 
comprising the element identifier encrypted with a third public key arid a third 
random encryption factor and the element of information re-encrypted with the 
third public key and the third random encryption factor, the element identifier 
encrypted with the third public key and the third random encryption factor having 
a second underlying plaintext; and 

(e) performing a distributed plaintext equality test to identify at least 
one of the second plurality of request pairs in which the second underlying 
plaintext is identical to the first underlying plaintext. 

1 9. (Original) The method of claim 1 8 wherein the first public key, the second 
public key, and the third public key are a single public key. 

20. (Original) The method of claim 18, the method further comprising, after 
step (e), the step of applying asymmetric proxy re-encryption to the at least one 
of the second plurality of request pairs in which the second underlying plaintext is 
identical to the first underlying plaintext to obtain at least one response pair, each 
of the at least one response pair comprising the element of information encrypted 
with a fourth public key and the consumer identifier. 

21 . (Original) The method of claim 20 wherein quorum-controlled asymmetric 
proxy re-encryption is applied to the at least one of the second plurality of 
request pairs in which the second underlying plaintext is identical to the first 
underlying plaintext to obtain at least one response pair, each of the at least one 
response pair comprising the element of information encrypted with the fourth 
public key and the consumer identifier. 
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22. (Original) The method of claim 21 , the method further comprising, after 
step (e), the step of making the element of information encrypted with the fourth 
public key available to the consumer based on the consumer identifier. 

23. (Original) The method of claim 22 wherein the step of making the element 
of information encrypted with the fourth public key available to the consumer 
based on the consumer identifier comprises transmitting the element of 
information encrypted with the fourth public key to the consumer in response to 
the consumer identifier. 

Claims 24-25 (Canceled). 

26. (Currently Amended) The method of claim 7-9_wherein: 

the elements of data associated with the first and second consumers 
includes demographic information about the first and second consumers, 
respectively; 

receiving the first information request includes receiving a first selection of 
advertisements from a plurality of advertisements, the first selection of 
advertisements being based on the demographic information about the first 
consumer; and 

receiving the second information request includes receiving a second 
selection of advertisements from a plurality of advertisements, the second 
selection of advertisements being based on the demographic information about 
the second consumer. 



